Back to skill

Security audit

Wanpaike Opc Tech Due Diligence

Security checks across malware telemetry and agentic risk

Overview

The skill is broadly aligned with technical due diligence, but it handles sensitive business and personal data and includes external knowledge-base persistence without clear consent or retention controls.

Install only if you are comfortable giving the skill access to confidential project materials, team/person background data, web search, local files, and IMA credentials. Before using IMA import or report writeback, confirm where documents and reports are stored, who can access them, how long they remain, and how to delete or redact them. Treat generated scores, BP suggestions, valuation comments, and investment recommendations as draft analysis requiring independent verification.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill states that it only evaluates technical authenticity, but later workflow steps instruct it to provide BP revision advice, financing-term adjustments, and valuation guidance. This scope drift can cause the agent to act outside the user's expected trust boundary, producing higher-risk advisory output without clear consent or safeguards.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The boundary section says the skill does not do BP writing, valuation, or operational advice, yet later sections require BP modification suggestions and financing-term recommendations. Contradictory instructions increase the chance of unsafe or misleading outputs because downstream users may rely on the restrictive boundary while the agent is actually guided to exceed it.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill advertises technical due-diligence and verification capabilities, but the implementation only reformats caller-supplied findings into a polished report without performing any independent validation. This can mislead users into trusting unverified claims, enabling deceptive investment memos or false assurance in high-stakes diligence workflows.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The documentation presents the tool as generating a technical due-diligence report, but all substantive judgments such as scores, advice, and verification outcomes are accepted directly from input. In context, this is dangerous because it creates an appearance of analytical rigor while merely echoing untrusted data, which can be abused to legitimize fabricated assessments.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
文档要求使用 append_doc 将最终尽调报告写回 IMA 知识库,属于持久化写入行为,而该技能对外宣称主要是初筛/评估工具。若未经明确用户同意就保存客户材料分析结果,可能导致敏感商业信息、团队背景核查结论和风险判断被长期留存,扩大泄露面和合规风险。

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The compliance routine prints a passing result and returns True unconditionally, even if earlier checks detected warnings or failures. In a due-diligence verification tool, this can mislead operators into trusting incomplete or noncompliant reports, creating integrity risk and potentially enabling bad investment or review decisions based on false assurance.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill directs collection and verification of sensitive team background, project documents, patents, and test reports, but provides no privacy, consent, retention, or lawful-processing guidance. In a due-diligence context, this increases the risk of unnecessary personal-data collection, mishandling confidential business information, and noncompliant use of third-party data sources.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
流程要求把客户提供的 BP、技术文档、专利文件等导入 IMA 知识库,但没有明确的用户提示、授权确认或隐私告知。由于这些资料通常包含商业机密、未公开专利信息和个人履历,未经充分告知的上传会造成数据处理透明度不足,并可能触发保密和合规问题。

Missing User Warnings

Medium
Confidence
96% confidence
Finding
将最终尽调报告写回知识库会持久化保存分析结论、风险评级和可能涉及个人/企业敏感判断,但文档未要求向用户做显式提示。该上下文是投资前技术与团队核查,内容高度敏感,因此无透明告知的持久化比普通文档写入更危险。

Missing User Warnings

Low
Confidence
88% confidence
Finding
流程规定在 IMA 无结果时使用网络搜索补充验证,但未提示项目名、团队成员、专利号等查询词可能被发送到外部服务。对尽调场景而言,这些检索词本身就可能泄露客户关注标的、未公开项目和调查方向,带来元数据暴露风险。

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.